Hardcoded Credentials in Vasion Print Virtual Appliance Host and Application
CVE-2025-34196
Key Information:
- Vendor
Vasion
- Vendor
- CVE Published:
- 29 September 2025
What is CVE-2025-34196?
Vasion Print products, specifically the Virtual Appliance Host and Windows client applications, exhibit serious security risks due to hardcoded credentials. The applications include a hardcoded private key for the Certificate Authority (CA) along with a password in configuration files. This exposes the CA certificate and sensitive settings through accessible configuration files like clientsettings.dat and defaults.ini. Malicious actors with access to these files can impersonate the CA, allowing them to sign certificates trusted by the client, conduct man-in-the-middle attacks, and compromise TLS communication security.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Print Application Windows * < 25.1.1413
Print Virtual Appliance Host Windows * < 25.1.102
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
